Falhas do tipo CWE-77

2.829 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2024-57212MEDIUMTOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_rebEPSS 0.8%CVE-2024-49560HIGHDell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low priviEPSS 0.8%CVE-2024-24551HIGHBludit - Remote Code Execution (RCE) through Image APIEPSS 0.8%CVE-2026-7849CRITICALCommand Injection in SCM (idledisconnect parameter)EPSS 0.8%CVE-2024-41135HIGHAuthenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.8%CVE-2024-41133HIGHAuthenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.8%CVE-2018-19013—An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a EPSS 0.8%CVE-2020-29547MEDIUMAn issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS,EPSS 0.8%CVE-2023-26430LOWAttackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be abused to access SIEPSS 0.8%CVE-2024-28136HIGHPHOENIX CONTACT: command injection gains root privileges using the OCPP remote serviceEPSS 0.8%CVE-2025-62222HIGHAgentic AI and Visual Studio Code Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-24132HIGHOrval Mock Generation Code Injection via constEPSS 0.7%CVE-2024-7679HIGHImproper neutralization special element in hyperlinksEPSS 0.7%CVE-2025-63406HIGHAn issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToEPSS 0.7%CVE-2022-26415HIGHOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior EPSS 0.7%CVE-2026-23653MEDIUMGitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityEPSS 0.7%CVE-2023-21805HIGHWindows MSHTML Platform Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-49565HIGHRemote Code ExecutionEPSS 0.7%CVE-2024-48830HIGHDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special ElementsEPSS 0.7%CVE-2026-30461HIGHDaylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/InsEPSS 0.7%